2016-05
Standard Bank of South Africa was tied to a 2016 ATM cash-out in Japan in which forged cards using stolen customer-card data were used to withdraw about $18–19 million from roughly 1,700 ATMs across Tokyo and 16 prefectures. UN Panel-linked evidence says …
🇿🇦 South Africa, 🇯🇵 Japan
#Finance
#ATM
#FinancialGain
2016-05
South Korean police attributed the GhostRAT compromise of domestic conglomerate networks to North Korea, reporting more than 130,000 infected computers and malware capable of keystroke logging, host profiling, microphone recording, remote-session control,…
🇰🇷 Korea, Republic of
#TCO!Stream
#DataBreach
#Espionage
#Defense
2016-04
BLACKSHEEP is preserved as an Andariel-linked South Korea incident through FSI’s Rifle campaign archive, which grouped BLACKSHEEP with other linked intrusions and malware cases assessed as activity by the same attacker. The available evidence is limited b…
🇰🇷 Korea, Republic of
#DataBreach
#Espionage
#Defense
2016-03
South Korean investigators attributed the Interpark breach and extortion case to North Korea’s Reconnaissance General Bureau after an employee PC was compromised via a spearphishing attachment, malware spread internally, and attackers reached systems used…
🇰🇷 Korea, Republic of
#DataBreach
#Retail
2016-02
The Bangladesh Bank BangSwift heist used authenticated SWIFT messages and custom malware tailored to SWIFT Alliance Access and an Oracle database environment to hide or manipulate transaction records, with reporting describing attempted transfers of rough…
🇧🇩 Bangladesh
#Finance
#SWIFT
#FinancialGain
2016-01
The INITROY incident involved a compromised financial information security company whose stolen code-signing certificate was used to make malware appear legitimate and distribute signed payloads to organizations via an academic association website server.…
🇰🇷 Korea, Republic of
#SupplyChain
#Technology
#SafePC
2015-12
In December 2015, attackers stole about $16 million from a Guatemalan financial institution. Carnegie’s financial-sector timeline and UN Panel reporting identify the case as a high-confidence DPRK-affiliated financial theft, but the linked evidence does n…
🇬🇹 Guatemala
#Finance
#FinancialGain
2015-05
Vietnam’s Tien Phong Bank reported an attempted theft of more than EUR 1 million through fraudulent SWIFT messages in 2015. Linked financial-incident and UN Panel reporting place the case within the broader DPRK/Lazarus-associated pattern of SWIFT-enabled…
🇻🇳 Viet Nam
#Finance
#SWIFT
#FinancialGain
2015-01
In January 2015, Ecuador’s Banco del Austro lost about $12 million after attackers used compromised payment systems to send fraudulent SWIFT transfers, routing much of the money to companies in Hong Kong. Carnegie reporting says the bank recovered about $…
🇪🇨 Ecuador
#Finance
#FinancialGain
2014-12
The KHNP incident combined destructive-malware emails, compromised KHNP-related mail accounts, stolen employee, retiree, and contractor documents, public leak-and-shutdown threats, and limited host impact rather than disruption of nuclear plant operations…
🇰🇷 Korea, Republic of
#DataBreach
#Espionage
#Utility
2014-12
The Sony Pictures Entertainment attack involved Lazarus-linked Blockbuster malware with dropper, proxy, cleanup, credential-based lateral movement, C2 log reporting, and destructive disk/file wiping components. Evidence from Operation Blockbuster connecte…
🇺🇸 United States
#Destruction
#Entertainment
2014-07
Seoul Metro reported a multi-month compromise of office PC management infrastructure for subway lines 1 through 4, affecting 58 infected PCs, abnormal access involving 213 PCs, and loss of control over PC management and webzine servers. Investigators said…
🇰🇷 Korea, Republic of
#Transportation
#Espionage
2013-06
The June 25, 2013 cyberattack wave targeted South Korean government, political, military, and media-related sites with DDoS, outages, defacements, data exposure, and destructive malware timed to the Korean War anniversary. Technical evidence included comp…
🇰🇷 Korea, Republic of
#Government
#Destruction
2013-03
The “Whois Team” attacks against South Korean targets in March 2013 involved coordinated cyberattacks on banks and broadcasting companies, where systems were disrupted and in some cases rendered unusable, accompanied by website defacements and propaganda …
🇰🇷 Korea, Republic of
#Finance
#Media
#Destruction
2012-06
South Korean police attributed the June 2012 JoongAng Ilbo intrusion to North Korean-linked activity by an attacker using the alias IsOne after examining compromised newspaper production systems, logs, malware, and relay servers. The attacker prepared fro…
🇰🇷 Korea, Republic of
#Media
#Destruction